pr_01m47d24b0e6n91zwymwxg0vpx/services/identity/wrangler.jsonc

55 lines2,414 bytesCodeBlame
1{
2 "$schema": "../../node_modules/wrangler/config-schema.json",
3 "name": "g1t-identity",
4 "account_id": "1e6f2cffa3f445920836e8ebe446bb58",
5 "compatibility_date": "2026-09-26",
6 // Runs next to its database: a request makes several queries in turn,
7 // and each would otherwise cross the distance to it.
8 "placement": { "mode": "smart" },
9 "main": "build/index.js",
10 "build": { "command": "cargo install -q worker-build@0.8.7 && worker-build --release" },
11 // Reached only through service bindings.
12 "workers_dev": false,
13 "d1_databases": [
14 {
15 "binding": "DB",
16 "database_name": "g1t",
17 "database_id": "b7d49c93-2666-4006-a3c3-073a01838dc9",
18 "migrations_dir": "migrations"
19 }
20 ],
21 "send_email": [{ "name": "EMAIL", "remote": true }],
22 // Uploaded avatars, keyed by the SHA-256 of their bytes. Only this
23 // service writes them; the site reads them to serve /avatars/<hash>.
24 "kv_namespaces": [{ "binding": "AVATARS", "id": "e627b571f07047e187c03e1fc2b3bbdd" }],
25 // Renaming a workspace publishes workspace.renamed, so every service
26 // moves what it keeps under the old slug.
27 "services": [
28 { "binding": "EVENTS", "service": "g1t-events" },
29 // Deleting a workspace asks whether it still holds repositories or
30 // projects, and has billing settle it first (src/deletion.rs).
31 { "binding": "REPOS", "service": "g1t-repos" },
32 { "binding": "PROJECTS", "service": "g1t-projects" },
33 { "binding": "BILLING", "service": "g1t-billing" }
34 ],
35 // Signing in with GitHub (src/github.rs), through g1t's GitHub App.
36 // Its client ID is public. Secrets: GITHUB_APP_CLIENT_SECRET, the app's
37 // client secret, and IDENTITY_KEY, 64 hex characters, which seals the
38 // GitHub user tokens kept for each linked account. Without the client ID
39 // and secret, nobody is offered GitHub sign-in.
40 //
41 // Invites (src/invites.rs): g1t.sh is invite-only, so every new account
42 // needs an invite code; "open" lets anyone register. Unset means
43 // invite. Each person may have INVITES_PER_USER invites out, each
44 // working INVITE_TTL_DAYS; owners of INVITE_STAFF_WORKSPACES (g1t's own)
45 // have no limit. IDENTITY_KEY also seals invite codes so their makers
46 // can copy them again.
47 "vars": {
48 "GITHUB_APP_CLIENT_ID": "Iv23liZS94alfjIUn1eW",
49 "REGISTRATION_MODE": "invite",
50 "INVITES_PER_USER": "5",
51 "INVITE_TTL_DAYS": "30",
52 "INVITE_STAFF_WORKSPACES": "flagon-io"
53 },
54 "observability": { "enabled": true }
55}